Lazarus Group's New Mach-O Man Attack Elevates Threat Level: CertiK
Security experts have warned of a new campaign, dubbed 'Mach-O Man', which transforms ordinary business communications into a direct conduit for credential theft and data loss. The Lazarus Group, a state-run collective with estimated cumulative loot of $6.7 billion since 2017, is targeting high-value executives and firms in the fintech and cryptocurrency sectors. According to Natalie Newson, a senior blockchain security researcher at CertiK, the group's activity level has increased significantly, with over $500 million siphoned from the Drift and KelpDAO exploits in the past two weeks alone. The crypto industry is advised to view Lazarus as a constant and well-funded threat, rather than just a news headline. The Mach-O Man campaign utilizes a modular macOS malware kit, created by Lazarus Group's Chollima division, which employs a social engineering technique known as ClickFix to deliver the malware. This technique involves sending executives fake meeting invites, leading them to a convincing website that instructs them to paste a command into their terminal to 'fix a connection issue', thereby granting immediate access to corporate systems and financial resources. Variations of this attack have already been identified, with cases of Lazarus attackers hijacking DeFI project domains and replacing their websites with fake messages. The malware is designed to erase itself after a breach, making it challenging for victims to detect and identify the attack.